Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > MISCELLANEOUS > Archives > Bug Report 1.4.x

Post Reply
 
Thread Tools
  #11  
Old 09-11-2005, 09:11 PM
-okapi-'s Avatar
-okapi- Offline
pixelpost guru
 
Join Date: Feb 2005
Location: Vienna, Austria
Posts: 252
this is the text of the last weird mail.

Quote:
a new comment has been made on the following image:



http://www.a-visual-notebook.at/?sho...al-notebook.at Content-Type: multipart/mixed; boundary=\"===============2075257112==\" MIME-Version: 1.0 Subject: 5490578 To: ahgtqoy@a-visual-notebook.at bcc: jrubin3546@aol.com From: ahgtqoy@a-visual-notebook.at This is a multi-part message in MIME format. --===============2075257112== Content-Type: text/plain; charset=\"us-ascii\" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit sdfgmqdx --===============2075257112==--

the comment is:
----------------------------------------------------------------------

ahgtqoy@a-visual-notebook.at

by ahgtqoy@a-visual-notebook.at

----------------------------------------------------------------------

(email sent by pixelpost)

the sender was:

ahgtqoy@a-visual-notebook.at <ahgtqoy@a-visual-notebook.at>

now i was test-commenting some images, and there was no email notification at all.

EDITED, because i added the snippet at the wrong lines.
__________________
a visual notebook
michael singer photography
http://www.a-visual-notebook.at
Reply With Quote
  #12  
Old 09-11-2005, 09:27 PM
raminia's Avatar
raminia+ Offline
Team Pixelpost
 
Join Date: Jan 2005
Location: FL, US
Posts: 3,706
Send a message via Yahoo to raminia
read my recent post that was about adding new codes. it was edited!
__________________
Photoblog: http://pblog.raminia.com Powered by Pixelpost 1.7
Reply With Quote
  #13  
Old 09-11-2005, 09:47 PM
-okapi-'s Avatar
-okapi- Offline
pixelpost guru
 
Join Date: Feb 2005
Location: Vienna, Austria
Posts: 252
Quote:
Originally Posted by raminia
read my recent post that was about adding new codes. it was edited!
thank you ramin!

now it works. and thanks for your comment on the latest image, now the notification did work!
as soon as there is a number in the name of the commenter, there is no email notification. i assume that this is the purpose of your code snippet?
as i have tested it with names like "tester 2", there was no notification.
__________________
a visual notebook
michael singer photography
http://www.a-visual-notebook.at
Reply With Quote
  #14  
Old 09-12-2005, 05:41 AM
n0d3 Offline
forum loafer
 
Join Date: Feb 2005
Location: localhost
Posts: 17
Send a message via ICQ to n0d3 Send a message via MSN to n0d3
Hi Raminia, I do not use popup comments either. This is what my spam looks like in my inbox: www.two-am.org/spam.jpg

Btw, do I remove the code from the first solution or do I leave it there as well?
Reply With Quote
  #15  
Old 09-12-2005, 06:26 AM
raminia's Avatar
raminia+ Offline
Team Pixelpost
 
Join Date: Jan 2005
Location: FL, US
Posts: 3,706
Send a message via Yahoo to raminia
@n0d3 you can keep the lat mod. it was ok

@okapi
That's nice to hear it works. I looks at the ID of photo from the HTML page. if it is not a numeric value it will show a blank page and exits. the hacker tries to substitute the default hidden value in the form from image id to its email address. I think it is machine that do this. it's quite silly (or very clever that I don't understand). It does not do anything bug annoying. Now if it does that, PP will stop responsing to it.

about notification for somebody with number in his/her name, it shouldn't stop notofiying.... are you sure?
__________________
Photoblog: http://pblog.raminia.com Powered by Pixelpost 1.7
Reply With Quote
  #16  
Old 09-12-2005, 06:29 AM
raminia's Avatar
raminia+ Offline
Team Pixelpost
 
Join Date: Jan 2005
Location: FL, US
Posts: 3,706
Send a message via Yahoo to raminia
btw, could you send me the raw content of the spam notification emails?

not the HTML view that you see on your email software but the message source.
__________________
Photoblog: http://pblog.raminia.com Powered by Pixelpost 1.7
Reply With Quote
  #17  
Old 09-12-2005, 09:17 AM
n0d3 Offline
forum loafer
 
Join Date: Feb 2005
Location: localhost
Posts: 17
Send a message via ICQ to n0d3 Send a message via MSN to n0d3
Ok, droppped you a PM. Thanks for the help!
Reply With Quote
  #18  
Old 09-12-2005, 05:46 PM
raminia's Avatar
raminia+ Offline
Team Pixelpost
 
Join Date: Jan 2005
Location: FL, US
Posts: 3,706
Send a message via Yahoo to raminia
I've made a glance. no time for more investigation for now.
it seems it filles every form field blindly with its email address in hope to get something emailed to itself.


there is no such vulnerability in pp. just annoys.
__________________
Photoblog: http://pblog.raminia.com Powered by Pixelpost 1.7
Reply With Quote
  #19  
Old 10-07-2005, 05:14 PM
funktifeye Offline
forum loafer
 
Join Date: Sep 2005
Location: Los Angeles, CA
Posts: 13
Not sure if this is the same issue, but I've been getting a ton of notifications that simply say:

Quote:
Hello,
A new comment has been made on your photoblog.

http://www.funktifeye.com/plog/?showimage=


The Comment is:
----------------------------------------------------------------------

by -
----------------------------------------------------------------------
Powered by Pixelpost
__________________
funktif[eye] photo blog
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 09:53 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs